Errata overview
Errata ID 443
Date 2017-07-13
Source package openssl
Fixed in version 1.0.2k-1~bpo8+1~ucs41.134.201706081137
Description
This update addresses the following issues:
* Montgomery multiplication may produce incorrect results (CVE-2016-7055)
* SSL/TLS SSL3_AL_WARNING undefined alert DoS (CVE-2016-8610)
* Truncated packet could crash via OOB read (CVE-2017-3731)
* BN_mod_exp may produce incorrect results on x86_64 (CVE-2017-3732)
* EXPORT and LOW ciphers have been disabled
Additional notes
CVE ID CVE-2016-7055
CVE-2016-8610
CVE-2017-3731
CVE-2017-3732
UCS Bug number #42925